Process Interaction Ratio Analysis for Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise networks face challenges in detecting malicious behavior due to the vast scale and dynamic nature, which makes it difficult to monitor process behavior effectively, leading to time-consuming and costly incident validation and remediation.
Innovation Solution
An automated system analyzes process interaction ratios (PIR) by calculating the z-score for each process, identifying potentially malicious activities based on deviations from historical means, and confirming malicious behavior by excluding newly introduced computing devices or users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional process monitoring methods are used in enterprise networks, then comprehensive coverage of all processes can be achieved, but the complexity of analyzing and validating malicious incidents increases significantly
Solution Approach 1:
The patent extracts and focuses on specific critical parameters (process interaction ratios, PIR z-scores) from the vast amount of process data, rather than analyzing all process attributes. This extraction approach enables effective malicious behavior detection while avoiding the complexity of comprehensive process analysis.
Solution Approach 2:
The patent transforms process monitoring from tracking absolute process counts to analyzing interaction ratios and statistical deviations (z-scores). This parameter transformation converts raw process data into meaningful security indicators, improving detection reliability while reducing analysis complexity.
2Measurement precision
If manual validation and remediation of malicious incidents are performed, then accurate security assessment can be achieved, but time consumption and costs increase significantly
Solution Approach 1:
The system performs self-service by automatically detecting, validating, and responding to malicious incidents using process interaction ratio analysis. The automated generation of PIR z-scores and anomaly detection eliminates the need for manual incident validation, reducing both time loss and operational costs while maintaining detection accuracy.
3Adaptability or versatility
If the network allows dynamic introduction of new devices and users, then network flexibility and scalability are improved, but the difficulty of tracking and monitoring process behavior increases
Solution Approach 1:
The process interaction ratio metric serves multiple functions simultaneously: it tracks process execution patterns, identifies anomalies, adapts to new devices and users, and detects malicious behavior. This universal metric works effectively regardless of network dynamics, maintaining tracking effectiveness while preserving network flexibility.
Data Source
AI summary
Systems and methods for detecting malicious behavior in a network by analyzing process interaction ratios (PIRs) are provided. According to one embodiment, information regarding historical process activity is maintained. The historical process activity includes information regarding various processes hosted by computing devices of a private network. Information regarding process activity within the private network is received for a current observation period. For each process, for each testing time period of a number of testing time periods within the current observation period, a PIR is determined based on (i) a number of unique computing devices that hosted the process and (ii) a number of unique users that executed the process. A particular process is identified as potentially malicious when a measure of deviation of the PIR of the particular process from a historical PIR mean of the particular process exceeds a pre-defined or configurable threshold during a testing time period.


